On July 22, the FCA partnered with Anthropic.
Not published a white paper. Not issued a consultation. Not delivered another speech.
Partnered. With the company that makes Claude.
Anthropic is now officially supporting the FCA’s Supercharged Sandbox — providing Claude Code and Claude Cowork to 21 financial services firms testing AI agents in a regulator-monitored environment. Scottish Widows is in the cohort. So are TrueLayer, Money Advice Trust, and 18 other firms selected from 199 applicants — a 51% increase from the first group.
The use cases being tested include agent-led payments, fraud detection, AI governance, and compliance automation. The FCA also launched the Agentic Academy — a 10-week specialist AI programme for financial firms.
This is not a pilot. This is not a trial balloon. This is the UK’s primary financial regulator provisioning Claude to sandbox firms and watching what happens.
For finance agencies running Meta campaigns for regulated clients, this changes everything.
The Speech Predicted This. The Partnership Confirmed It.
Just seven days before the Anthropic announcement, FCA Chief Executive Nikhil Rathi told the techUK “Agents of Change” conference that the next phase of AI would produce “systems that don’t just support financial decisions, but coordinate and transact.” He was explicit: “Accountability for regulated activities and outcomes must remain clear.”
The speech was the rhetorical signal. The partnership is the concrete action.
One week. That’s how fast the FCA moved from “we’re thinking about agentic AI” to “we’re testing it with Anthropic.” And the demand was overwhelming — 199 applications for 21 spots. Financial services firms aren’t waiting to be told to use AI. They’re lining up to test it under regulatory supervision.
The FCA’s Jessica Rusu put it plainly: “The high level of interest in the Supercharged Sandbox demonstrates the demand for trusted environments where firms can experiment safely and responsibly.”
“Trusted environments.” “Safely and responsibly.” “Accountability must remain clear.”
Those aren’t buzzwords. They’re the new compliance requirements for any financial services firm using AI — including the agencies that manage their advertising.
The Compliance Question Changed
Before July 22, the conversation around AI in financial advertising was theoretical. Is it safe? Should agencies use it? What if something goes wrong?
After July 22, the conversation is operational. The regulator is watching AI agents transact in financial services right now. When the sandbox graduates to enforcement — and it will, because the FCA’s financial ads taskforce is already active — the question won’t be “do you use AI for campaign management?”
The question will be: Can you prove what your AI did?
Three questions every finance agency needs to be able to answer:
- Who made this campaign change? Not which system. Which person — or which agent acting under whose authority.
- When and with what approval? Timestamped, with a before/after record showing the exact delta.
- Show the immutable audit trail. Exportable, regulator-ready, in minutes — not days.
If your agency can’t answer all three, you don’t have an AI strategy. You have a liability.
Generalist AI Builds Campaigns. Compliance-Ready AI Survives Audits.
This is where the gap opens between horizontal AI platforms and compliance-ready infrastructure.
Supermetrics can now create Meta, Google, LinkedIn, and TikTok campaigns from Claude. The campaigns are created in a paused state — a sensible safety feature. But there’s no actor attribution in the activity log. No immutable before/after record of every change. No jurisdiction-aware compliance context. A Supermetrics+Claude workflow will build a campaign for a forex broker. It won’t survive a regulatory audit of that campaign.
Synter has 221 blog posts, a credit-based pricing model, and a dry-run protocol for campaign creation. Zero of those 221 posts mention compliance, audit trails, or regulated verticals. Synter builds campaigns. It doesn’t build campaigns that a regulator can inspect.
This isn’t a criticism of either platform. They’re built for horizontal PPC — ecommerce, DTC, B2B. They weren’t designed for the scenario where a regulator asks “who changed this forex broker’s campaign budget at 2 AM and why?” That scenario didn’t exist when they were built.
It exists now.
The FCA’s Critical Third Parties regime — announced July 10 — extends the regulatory perimeter to include technology vendors serving financial firms. The tools your agency uses to manage regulated client campaigns may face indirect regulatory pressure. If your analytics platform can’t produce an audit trail, the liability doesn’t stay with the platform. It lands on your agency.
What “Audit-Ready” Actually Means
If the FCA or another regulator audits one of your finance clients’ Meta campaigns, here’s what they’ll want to see — and here’s what Ott’s infrastructure delivers.
Activity Logging with Actor Attribution
Every campaign change — budget adjustments, bid changes, creative swaps, pausing, restarting — is logged with a timestamp, the person (or system) that made the change, and the before/after values. Not “campaign budget changed.” But “Campaign #8472 budget changed from £500 to £750 by [media buyer name] at 14:32:17 UTC on 22 July 2026. Approval: [manager name] at 14:28:04 UTC.”
When the regulator asks “who changed this, when, and why?” — you have the answer. In one query. Exportable.
Campaign Triage Across All Business Managers
Red/Amber/Green severity flags across every campaign, across every Business Manager. Your morning scan catches spend anomalies, CPM spikes, and CTR drops before they become compliance incidents. A campaign overspending on a regulated client isn’t just a budget problem — it’s a potential regulatory violation. Triage catches it in 90 seconds instead of 30 minutes of manual BM-hopping.
Client → Brand → Account Hierarchy
A forex broker with three regulated brands (UK, EU, offshore) doesn’t have campaigns mixed together in a flat list. Each brand has its own audit boundary. Client permissions cascade through the hierarchy. When the regulator audits Brand A, you export Brand A’s activity log — not the entire agency’s. The structure maps to the regulated entity structure.
Telegram CAPI Tracking
For finance agencies using Telegram as a conversion channel — forex signal providers, crypto exchanges, iGaming affiliates — per-ad attribution traces every join, CPJ, FTD, and deposit back to the specific Meta campaign that drove it. When the regulator asks “where did this lead come from and what ad did they see?” — the full conversion path is in the audit trail.
The 90-Second Audit Export
This is the difference between passing and failing. Not “we’ll pull that together in a few days.” Not “spreadsheets across three team members with different naming conventions.” A single export — select the client, export the activity log, deliver to the regulator. Timestamped. Person-attributed. Immutable.
The Sandbox Is Running Now
The FCA is watching AI agents operate in financial services as of July 22, 2026. Twenty-one firms. Anthropic Claude. One hundred ninety-nine applicants. A 10-week Agentic Academy. Critical Third Parties regulation expanding the perimeter.
This isn’t a future scenario. It’s the current state of financial services regulation in the UK — and the trajectory is clear. The sandbox tests AI accountability. The sandbox graduates to guidance. The guidance becomes enforcement. The financial ads taskforce of July 16 already has the enforcement muscle flexed.
When that enforcement reaches AI-managed campaign operations — and it will — the question won’t be whether your agency uses AI for PPC.
It will be whether your AI can prove what it did.
Generalist platforms build campaigns.
Ott builds campaigns that survive audits.
Start your free trial and see the activity log in action — or book a demo to walk through a compliance audit scenario with your team’s data.